Intel

AIKIDO-2026-864797

@vendure/core is vulnerable to Improper Authorization

Improper AuthorizationGHSA-7qvr-c5vf-xxfh Published Today

99

Critical Risk

This Affects:

JS@vendure/core
0.16.0 - 3.7.2
Fixed in 3.7.3
Are you affected? Scan for Free

TL;DR

Payment and Refund entities are loaded by raw id in refundOrder and sibling money-movement operations without validating that the parent order belongs to the caller's active channel. A channel-scoped administrator can drive refunds and payment or fulfillment state transitions against orders in other channels, moving money across tenant boundaries. The fix routes these mutations through channel-scoped order validation before any state change or gateway call executes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you operate multiple channels with channel-scoped administrators.

Background info

@vendure/core is vulnerable to Improper Authorization in versions 0.16.0 - 3.7.2.

How to fix this

Upgrade the @vendure/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform